Skip to main content

Legal index

Orbit’s legal and trust materials split into two halves: the binding documents Devotel publishes (terms, privacy, the Trust Center) and the tenant-operated controls this docs site describes. Use this page as the map between the two: which document governs which relationship, which obligations land on Devotel versus on your own team, and where each control is documented.
This page is a directory, not legal advice. Your obligations depend on where your end users live and what data you process — confirm with qualified counsel.
If you are reviewing Orbit for procurement or vendor risk, read in this order — each document layers on the previous one:
  1. Terms of service — the contract between you and Devotel: acceptable use, service levels, liability, and governing law. Everything else hangs off this agreement.
  2. Privacy policy — what personal data Orbit collects to run the service, how long we keep it, and the rights you and your end users can exercise. Includes the do-not-sell portal for CCPA/CPRA opt-out of sale or sharing.
  3. Trust Center — the delivery vehicle for the commitments the ToS names: SOC 2 control mappings, the subprocessor registry with data-residency notes, and downloadable agreements (DPA, BAA).
  4. Security overview — how the platform enforces the Trust Center claims: encryption and network hardening, tenant isolation, key handling, and incident reporting.
Your legal team’s remaining checklist item after that pass is open source attribution, which covers the license notices for the OSS components Orbit redistributes.

Obligation map: document and owner

Every obligation a reviewer tries to place resolves to either a platform-owned document or a tenant-operated control. The mapping: The split matters in a review: Devotel-owned rows resolve by document review alone, while tenant-owned rows also require you to operate the named control.

Review-closure checklist

Work these steps in order. When every item is checked, your vendor review is closed.
  1. Execute the agreements that need signatures; review the rest. Only the DPA — and the BAA if your workload touches PHI — are executable once. Sign the DPA self-serve and add the BAA in the Trust Center rather than red-lining terms. The terms of service and privacy policy are review-only.
  2. Route the reading to the right reviewer. Split the remaining documents per role:
  3. Check the tenant-owned controls are green. Each advisor row in the obligation map passes only when its control is configured and passing in your organization — not merely documented here.
  4. Close the review. When the agreements above are executed and the role-specific checks are green, your vendor review is closed. File the executed DPA/BAA and the current checklist state in your vendor-risk record.

Tenant-operated controls

The documents above describe Devotel’s commitments. The guides below describe the controls you operate to back your own obligations — consent, suppression, DSAR intake, and the checks that gate every send. These are the entries a compliance reviewer actually walks through.

Compliance posture overview

Per-jurisdiction gates, quiet hours, and the posture check that runs before every send.

SOC 2 control ownership split

Which controls are platform-owned and which stay with your tenant.

HIPAA on Orbit

The BAA boundary and the controls for PHI workloads.

Consent management

Per-channel consent capture, lawful-basis tracking, and signed receipts.

Opt-out & suppression

Cross-channel suppression of opted-out recipients, with bulk CSV import.

Send gates

BAA, quiet hours, DNC, reassigned-numbers, and preference checks before a send.

Data subject requests (DSAR)

Operator-filed and self-service DSAR intake, and the fulfilment pipeline.

Self-serve DPA execution

Preview, sign, and download the GDPR Art. 28 Data Processing Agreement.

Binding versus advisory

Classify each surface before you rely on it:
  • Binding on Devotel — the terms of service, the privacy policy, and any executed agreement from the Trust Center (DPA, BAA). These create obligations on Devotel and on you.
  • Advisory — the security overview, the Trust Center reports, and every guide under /compliance and /legal on this docs site. These explain the platform and the controls; they do not amend the agreement.
When the two disagree, the binding layer governs. If a review question still doesn’t map onto either layer, route it to legal@devotel.io.